
A nuclear supply chain program held separate safety and cybersecurity reviews for the same system, each passing independently. Nobody checked whether a security-approved access control change restricted the same interface the safety case relied on for operator intervention. The author argues assurance cases must merge both disciplines into one argument.
Tap to vote and see what everyone thinks.
Summary by ByteBrief
Dropbox closes design-to-code security gap